Skip to content
Actively exploitedCVSS 7.8 · HIGH

CVE-2026-41091

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

View on NVD

Analysis

Microsoft Defender contains a vulnerability in link resolution that allows a local user to elevate their privileges. While high severity, this is a standard local privilege escalation bug that is typically handled by automated OS updates and does not represent a systemic risk to developer infrastructure.

Relevant roles

WindowsCyberSecurity

Severity

Score: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-59

CISA KEV

Added to KEV: 2026-05-20
Federal patch deadline: 2026-06-03
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.0655 (6.6%)
Percentile: 91.2%
EPSS: 2026-05-22

Affects

microsoft:malware_protection_engine

Technical description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Published: 5/20/2026, 1:16:29 PM
Last modified: 5/20/2026, 7:06:36 PM

References

HomeEventsBlogResourcesTeam